AlfaCleaner

AlfaCleaner is known to be distributed through exploits that also download adware/spyware on users' computers without notice or consent. When AlfaCleaner is downloaded through an exploit, it puts an icon in the system tray and shows a false warning that the computer is infected with spyware. It may also display pop-up warnings of spyware on the computer as a scare tactic.0

General information:

Malware Name:AlfaCleaner
Malware Type:Adware
Company Name:
Company URL:http://www.alfacleaner.com/
Threat Level:High
Operating System:WIN XP
Installation Type:Installed through EXE
Operation:Time of After Installation

Company Description:

Spyware Description:

AlfaCleaner is known to be distributed through exploits that also download adware/spyware on users' computers without notice or consent. When AlfaCleaner is downloaded through an exploit, it puts an icon in the system tray and shows a false warning that the computer is infected with spyware. It may also display pop-up warnings of spyware on the computer as a scare tactic.0

Characteristics/Symptoms:

    -> Collects information about the pages visited -> Shows popup ads -> It also associates with other Adwares -> Full-scale protection from keyloggers -> Automatically update the anti-virus base0

Additional information might be found here:

googleSearch at Google for AlfaCleaner
bingSearch at Bing for AlfaCleaner
yahooSearch at Yahoo for AlfaCleaner

Processes Running:

AlfaCleaner.exe

File information Created after Installation:

File LocationSize (Bytes)Type
C:\Program Files\AlfaCleaner\AlfaCleaner\Panels\common\dlgs\dlg_ref\warning_logo.PNG4855PNG Image
C:\Program Files\AlfaCleaner\AlfaCleaner\Panels\common\main\buttons\cleanup_wizard_deff.png2796PNG Image
C:\Program Files\AlfaCleaner\AlfaCleaner\Panels\common\main\buttons\cleanup_wizard_dis.png1607PNG Image

Folder information Created after Installation:

Folder Location
C:\Program Files\AlfaCleaner
C:\Program Files\AlfaCleaner\AlfaCleaner

Registry information Created after Installation:

Main Registry KeySub Registry KeyKey Value Name
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesEventlogSystemAlfaCleanerServiceEventMessageFile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AlfaCleanerService\Enum0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\AlfaCleanerServiceTypesSupported